Executive Summary
Aceville Pte Ltd is a Singapore-registered company that functions as the international legal wrapper for Tencent Cloud. Through a single RDAP NIC handle (APA7-AP โ "ACEVILLE PTELTD administrator"), it registers IP blocks that appear to be located in 10 different countries while all routing through AS132203 in Singapore. Our honeypot has tracked 181 IPs on this infrastructure, of which 156 carry abuse scores โฅ80 and 59 are classified "malicious" by GreyNoise. This is not a hosting provider with an abuse problem. This is a jurisdictional arbitrage architecture.
The Corporate Shell
Aceville Pte Ltd appears in exactly one public context that connects it directly to Tencent: the Hong Kong Trade Development Council Belt and Road portal. The HKTDC service-provider listing for Aceville does not describe an independent company. It describes Tencent Cloud โ attributing to Aceville the same data-center infrastructure, the same product lines, the same "leading cloud provider in China" narrative that Tencent uses in its own materials.
The entity exists for one purpose: to hold IP registrations in APNIC's Singapore jurisdiction, creating a legal buffer between Chinese cloud infrastructure and international reporting mechanisms.
The Numbers
| Metric | Value | Significance |
|---|---|---|
| Total tracked IPs | 181 | On AS132203 (Tencent) in our honeypot |
| Aceville-registered | 154 | 85% of Tencent traffic via SG shell |
| Abuse score โฅ 80 | 156 | 86% of all IPs flagged as abusive |
| GreyNoise "malicious" | 59 | 33% confirmed mass-scanning |
| AbuseIPDB score = 100 | 22 | Maximum abuse confidence |
| Average threat score | 53.5 | Significantly above global mean (~30) |
| Claimed countries | 10 | SG, US, JP, HK, BR, DE, ID, TH, IN, KR |
| Actual BGP routing | 1 (SG) | ALL traffic routes through Singapore |
The Geo-Discrepancy Architecture
This is the signature of the wrapper. Every IP registered to Aceville exhibits the same pattern:
- RDAP country: Varies (US, JP, SG, DE, HK, BR, ID, IN, KR, TH)
- BGP routing (Cymru): Always
SG - Abuse country: Matches RDAP claim (the fiction propagates)
The effect: when a victim in the US receives an SSH brute-force from 43.166.137.151, every database says "US". AbuseIPDB says US. MaxMind says US. Only BGP routing analysis reveals the truth โ this is a Singaporean-routed Chinese cloud instance pretending to be American.
| IP | Threat | Claims | Routes Through | RDAP Org |
|---|---|---|---|---|
43.128.237.224 | 100 | JP | SG | IRT-ACEVILLEPTELTD-SG |
124.156.202.242 | 100 | SG/IN | SG | IRT-ACEVILLEPTELTD-SG |
43.166.137.151 | 98 | US | SG | IRT-ACEVILLEPTELTD-SG |
43.173.69.147 | 93 | US/SG | SG | ACEVILLE PTE.LTD. |
43.133.148.170 | 89 | SG/ID | SG | IRT-ACEVILLEPTELTD-SG |
43.156.212.86 | 88 | SG | SG | IRT-ACEVILLEPTELTD-SG |
101.32.248.94 | 88 | SG | SG | IRT-ACEVILLEPTELTD-SG |
43.155.239.183 | 88 | SG/KR | SG | IRT-ACEVILLEPTELTD-SG |
43.157.98.118 | 82 | DE | SG | IRT-ACEVILLEPTELTD-SG |
43.167.157.240 | 70 | JP/SG | SG | ACEVILLE PTE.LTD. |
The NIC Handle: APA7-AP
A single RDAP entity โ NIC handle APA7-AP, name "ACEVILLE PTELTD administrator" โ controls 146 IP allocations visible in our database. This administrator contact is the sole technical reference for all Aceville-registered blocks across APNIC.
The handle format is standard APNIC: "APA" (Aceville Pte administrator) + "7" (sequential) + "-AP" (Asia-Pacific region). What's unusual is the scale: 146+ netblocks managed through a single administrative contact with no published abuse-handling team, no NOC contact, no network operations presence distinct from the parent Tencent infrastructure.
The Tencent Connection
What we can document
- AS132203 is named "TENCENT-NET-AP-CN - Tencent Building, Kejizhongyi Avenue, CN"
- HKTDC Belt and Road portal lists Aceville as providing Tencent Cloud services
- PeeringDB lists AS132203 as "Tencent Global" with 1000 IPv4 prefixes
- Tencent Cloud's international product (tencentcloud.com) serves from the same IP ranges
- All Aceville IPs route through Tencent's Singapore POP
What this means
Aceville is not a customer of Tencent. Aceville is Tencent โ the international face that holds registrations in a jurisdiction where Chinese cybersecurity law doesn't apply and where Singaporean regulators have neither mandate nor resources to police cloud abuse originating from 181 IPs spread across 10 claimed countries.
The Abuse Reporting Dead End
Consider the practical effect. A security researcher detects SSH brute-forcing from 43.166.137.151. They look up the IP:
- GeoIP: United States
- AbuseIPDB: Country = US, ISP = "Aceville Pte Ltd"
- Abuse contact: Points to an APNIC handle in Singapore
Where do they report? The US has no jurisdiction (the IP doesn't physically exist there). Singapore's PDPC regulates data privacy, not network abuse. China's CERT handles domestic networks only. The traffic routes through SG but claims US residency. There is no entity with both jurisdiction and enforcement capability.
This is the wrapper's function. Not to hide the infrastructure โ it's easily discoverable โ but to ensure that discovery leads nowhere actionable.
Exposed Services
Shodan data for the high-threat Aceville IPs reveals:
| IP | Threat | Open Ports | Notable |
|---|---|---|---|
43.128.237.224 | 100 | 80 | HTTP server (C2 panel?) |
124.156.202.242 | 100 | 5000 | Custom service (non-standard) |
43.173.69.147 | 93 | 80, 443 | Web server (credential harvesting?) |
43.133.148.170 | 89 | 80, 443, 3008, 8080 | Multi-service deployment |
43.155.239.183 | 88 | 443, 3306 | Exposed MySQL + HTTPS |
43.163.107.154 | 83 | 22, 443, 3000 | SSH + Grafana/Gitea port |
The presence of non-standard ports (3008, 5000, 3000) combined with maximum threat scores suggests these are purpose-built attack infrastructure โ not legitimate services with a security problem.
Scale in Context
The Pattern
This is not unique to Tencent. It's a template used by every major Chinese cloud provider expanding internationally:
- BytePlus (TikTok/ByteDance) โ Singapore shell โ AS150436 โ 45+ malicious IPs
- UCloud โ "UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED" โ AS135377 โ 124+ IPs
- Yisu Cloud โ Hong Kong shell โ AS138152/142403 โ 28+ IPs, bulletproof designation
- CDS Global Cloud โ US registration, Chinese tech contact โ AS63199 โ 4 IPs ALL at 95-100
The Cloud Silk Road series will trace each of these threads. This first letter establishes the archetype. Aceville is not an outlier โ it's the most visible instance of the most common Chinese cloud internationalization pattern.
Implications
For defenders
GeoIP databases are weaponized against you. An IP claiming "US" that routes through SG on a Chinese ASN is not American infrastructure. BGP-path analysis is the only reliable geographic indicator for Aceville ranges. Treat 43.x.x.x blocks on AS132203 as Chinese cloud regardless of claimed location.
For regulators
The wrapper model exploits the gap between registration jurisdiction (Singapore), routing jurisdiction (Singapore), claimed location (varies), and enforcement jurisdiction (nowhere). No single authority has both the mandate and the capability to act on abuse from these ranges.
For researchers
The RDAP handle APA7-AP is a single point of attribution for 146+ netblocks. Track this handle โ it grows quarterly as Tencent expands international capacity under the Aceville wrapper.